Data Retention Policy

Last updated: January 19, 2026

Overview

This policy explains how long we retain different categories of data and the legal basis for each retention period. We retain personal data only as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.

Our retention practices are designed to comply with GDPR, CCPA, UK GDPR, and the Australian Privacy Act.

Retention Periods by Data Category

Data CategoryRetention PeriodDeletion TriggerLegal Basis
Account InformationAccount lifetime + 7 yearsAccount deletion + 7 yearsLegal obligation (tax records)
Agent Execution Logs7-365 days (varies by plan)Automatic based on subscription tierLegitimate interests (debugging, support)
Email Processing Data30 daysAutomaticContract performance
Indexed KnowledgeConfigurable (default 2 years)Per source configuration or customer requestContract performance
Billing Records7 yearsAccount deletion + 7 yearsLegal obligation (tax records)
Audit Logs (UK/EU)3 yearsAutomaticRegulatory requirement (GDPR)
Audit Logs (Australia)2 yearsAutomaticRegulatory requirement (Privacy Act)
Audit Logs (US)1 yearAutomaticLegitimate interests (compliance)
Support Tickets3 yearsAutomatic after ticket closureLegitimate interests (support quality)
Marketing Consent RecordsUntil withdrawnCustomer requestConsent
Session Data24 hoursAutomaticContract performance
Analytics Data26 monthsAutomaticLegitimate interests (service improvement)

LinkedIn Integration Data Retention

LinkedIn data is subject to strict retention limits mandated by LinkedIn's API Terms of Use. These limits supersede our general retention policies and cannot be extended:

Data CategoryMaximum RetentionLegal Basis
Member Social Activity (posts, comments, reactions)48 hours maximumLinkedIn API Terms
Non-Authenticated Member Profile Data24 hours maximumLinkedIn API Terms
Organization Social Activity6 weeks (6 months if org authenticated)LinkedIn API Terms
Organization Admin & Reporting Data1 yearLinkedIn API Terms

Note: When LinkedIn data falls under multiple retention requirements, the most restrictive (shortest) period applies. We automatically purge LinkedIn data according to these schedules regardless of your subscription tier.

Deletion on Disconnection: When you disconnect your LinkedIn integration or terminate your account, all LinkedIn data is deleted within 10 days, which is faster than our general 30-day account termination policy, in compliance with LinkedIn's Marketing API Terms.

Retention by Subscription Tier

Some retention periods vary based on your subscription tier:

TierAgent LogsExecution HistoryKnowledge Base
Basic7 days30 days6 months
Professional30 days90 days1 year
Pro Plus1 year1 year2 years

Deletion Processes

Data is deleted through the following processes:

  • Automatic Deletion: Data subject to automatic retention periods is deleted by scheduled jobs that run daily.
  • Customer Request: Upon receiving a valid deletion request, we delete data within 30 days (GDPR) or 45 days (CCPA).
  • Account Termination: When you terminate your account, all customer data is permanently deleted within 30 days, except data required for legal compliance.
  • LinkedIn Integration Data: LinkedIn data is subject to accelerated deletion—deleted within 10 days of integration disconnection or account termination, per LinkedIn's Marketing API Terms.
  • Backup Retention: Backups may retain deleted data for up to 30 additional days for disaster recovery purposes before being purged.

Exceptions to Deletion

We may retain data beyond the stated retention periods in the following circumstances:

  • Legal Holds: When we are required to preserve data due to litigation, government investigation, or other legal requirements.
  • Tax and Accounting: Financial records required for tax compliance (typically 7 years).
  • Fraud Prevention: Data necessary to prevent fraud or enforce our terms of service.
  • Anonymized Data: Data that has been fully anonymized is no longer considered personal data and may be retained indefinitely for analytics.

Data Export Before Deletion

Before account termination or upon request, you may export your data in the following formats:

  • JSON: Machine-readable format for technical users
  • CSV: Spreadsheet-compatible format for business users

To request a data export, contact us at privacy@outermind.ai.

Third-Party Data Retention

Our sub-processors have their own data retention policies:

  • Microsoft Azure: Data deleted upon our request per our DPA
  • Stripe: Payment data retained per PCI-DSS requirements
  • Azure OpenAI: No data retention (zero data retention policy)

See our Sub-Processors page for the complete list.

Policy Updates

We may update this policy from time to time to reflect changes in our practices or legal requirements. Significant changes will be communicated through the Outermind dashboard or via email at least 30 days before they take effect.

Contact Us

For questions about our data retention practices, contact us at privacy@outermind.ai.